Guide · 2026-07-12

The Privacy Policy (Datenschutzerklärung): Required Content, Explained Simply

The privacy policy is the text almost nobody reads — yet every business website in Germany must have one. If it is missing or incomplete, you risk cease-and-desist letters (Abmahnungen) and, in serious cases, fines. The good news: the required content is clearly defined, and for most small businesses the effort is manageable. This guide explains the mandatory elements without legalese.

Illustration: document with a protective shield and lock, surrounded by cookie and data symbols — representing a website privacy policy

Why every business website needs a privacy policy

As soon as your website processes personal data, Art. 13 GDPR requires you to inform visitors — clearly, completely and at the time of collection. And practically every website processes personal data: merely opening a page transmits the visitor’s IP address to the server, plus there are contact forms, cookies and embedded services like Google Maps.

The rule of thumb: no business website without a privacy policy — whether you are a sole trader, a trade business or a GmbH. It must be easily reachable from every page; the standard solution is a dedicated footer link next to the Impressum. Important: the privacy policy and the Impressum are two separate legal obligations and belong on two separate pages.

The mandatory information under Art. 13 GDPR

The core of every privacy policy is the same for all companies. It must include:

  • Name and contact details of the controller — your business, with postal address and email
  • Contact details of the data protection officer, if you need one (generally only from 20 people regularly processing personal data)
  • Purposes of processing and the legal basis for each — e.g. consent (Art. 6(1)(a)) or legitimate interest ((f))
  • Recipients of the data: hosting provider, newsletter service, analytics tools — every service provider that receives data
  • Transfers to countries outside the EU, for example with US services, including the legal basis
  • Storage period, or the criteria used to determine it
  • Data subject rights: access, rectification, erasure, restriction, data portability, objection
  • The right to withdraw consent and the right to complain to a data protection authority

What a typical company website has to explain

The mandatory items stay abstract until you know which processing actually happens on your own site. For most small businesses it comes down to these building blocks: server log files from hosting (IP address, timestamp, page requested), the contact form and related email traffic, possibly a booking or appointment system, web analytics such as Google Analytics or privacy-friendly alternatives, and embedded third-party services — Google Maps, YouTube videos, social media plugins.

Each of these blocks needs its own section stating purpose, legal basis and recipient. Fonts are a special case: Google Fonts may no longer be loaded from Google’s servers without visitor consent — since a Munich court ruling in 2022 this has been a popular trap for warning letters. The clean solution is hosting fonts locally on your own server; then the topic disappears from your privacy policy entirely.

For cookies and similar technologies, § 25 TDDDG additionally applies: anything not technically necessary — marketing cookies, tracking pixels — requires active consent via a cookie banner. The privacy policy does not replace the banner; it documents it.

The most common mistakes — and what they cost

The classic mistake is the copied privacy policy: a text taken from someone else’s website that describes services you do not use — while omitting the ones you do. That is doubly risky: an inaccurate policy is legally hardly better than none at all, and the copy often infringes the original author’s copyright on top.

Also common: the website evolved, the privacy policy did not. A new booking tool, a newsletter form, a different analytics tool — every change to the website can mean new processing that must be explained. And finally the hide-and-seek approach: the policy exists only as a PDF, is reachable only via detours, or is missing entirely on landing pages.

The costs: warning letters from competitors or specialised law firms typically run between 500 and 2,000 euros, plus a cease-and-desist declaration with contractual penalties. In theory, Art. 83 GDPR allows fines of up to 20 million euros or 4 percent of annual turnover — for small businesses, actual regulatory fines usually stay far below that, but even a single warning letter costs more than years of proper maintenance.

Generator, lawyer or website provider: who writes the text?

For standard small-business websites, reputable privacy policy generators do a solid job — for example those from eRecht24 or specialised law firms. They ask which services you use and assemble the matching text. The key is honesty when filling them in: every service you actually use must be declared, and the result must not be trimmed by gut feeling afterwards.

A lawyer is worthwhile if you process special categories of data — such as health data in a medical practice —, run an online shop with customer accounts, or analyse data at scale. A one-off review usually costs 150 to 400 euros and is cheaper than a single warning letter.

If a provider manages your website, clarify who maintains the legal texts. With a website subscription like ours, entering and updating the privacy policy is part of ongoing care — including adjustments when new features such as booking or a newsletter are added. Legal responsibility for accuracy remains with the business, but you do not have to work through the legal paragraphs yourself.

Keeping it current: when the privacy policy must be updated

A privacy policy is not a one-off document but a mirror of your website. The simplest rule: with every functional change to the site, briefly check whether new processing has been added.

  • Added a new tool (booking, newsletter, chat, analytics)? Add the section before it goes live
  • Switched providers (hosting, email)? Update recipients and any third-country notes
  • Changed the cookie banner? Check that banner and policy still say the same thing
  • Re-read everything once a year: does the text still describe the real website? 15 minutes that prevent warning letters

Frequently asked questions

Do I need a privacy policy if I do not use cookies?

+

Can I copy the privacy policy from another website?

+

Is a free privacy policy generator enough?

+

Do I need a data protection officer?

+

What does a missing or faulty privacy policy cost?

+

Website subscription — from €79/month

Custom web design, German hosting, maintenance and personal support in one monthly package.

Book a free consultation

← All guide articles